Friday, September 11, 2020

Digital Forensics: How to Forensics image with CAINE Live USB/DVD Linux bootable

Digital Forensics: How to Forensics image  with CAINE Live USB/DVD


CAINE (Computer Aided Investigative Environment) is an Italian GNU/Linux live distribution created as a Digital Forensics project.

CAINE 11 - GNU/Linux Live Distribution For Digital Forensics Project, Windows Side Forensics And Incident Response 

CAINE 11.0 "Wormhole" 64bit - Official CAINE GNU/Linux distro latest release. 

The important news is that CAINE 11.0, 10.0, 9.0, 8.0 and 7.0 block all the block devices (e.g. /dev/sda), in Read-Only mode. You can use a tool with a GUI named UnBlock present on Caine's Desktop.

This new write-blocking method assures all disks are really preserved from accidentally writing operations, because they are locked in Read-Only mode.

By: https://www.caine-live.net


Tools

- CAINE 11 Live USB/DVD

-Kingston data Traveler_3.0  15.5 GB  (Evidence)

-Laptop Workstation 


After CAINE boots, choose the "Boot Live system". If all goes well, the following desktop should appear:

หลังจาก Boot ด้วย CAINE

CAINE  can boot on Uefi/Uefi+secure boot/Legacy Bios/Bios.

CAINE  can boot to RAM




CAINE has a utility called Mounter, which is located in the task bar. It's the tiny icon circled above. Double clicking this icon brings up a dialog box that shows which block devices are currently mounted:

From the CAINE website documentation:

This new write-blocking method assures all disks are really preserved from accidentally writing operations, because they are locked in Read-Only mode.
If you need to write a disk, you can unlock it with BlockOn/Off or using "Mounter" changing the policy in writable mode. 

1. เราจะทำ Forensic image  /dev/sdb1  evidence  สถานะ Read-only

   sdb Read-Only disk

การเขียนข้อมูลลง External HDD ที่เป็นระบบ NTFS ต้องทำการเขียนคำสั่ง - #sudo ntfs-3g -o rw /dev/sda4 /media/sda4

2.จะทำการ สร้าง Folder CF010 และเก็บไฟล์ CF010.e01 ไว้ที่ /dev/sda4  สถานะ Writable  /Media/sda4/CF010

3 Check Timezone and Date time Setting

4.ตั้งชื่อ Case Number ,Evidence number   CF010.e01

5.เปิดโปรแกรม Guymager เลือก  Forensic image  /dev/sdb  Kingston data Traveler_3.0  15.5 GB 

just start GuyMager (which is the imaging software we will use). A link to Guymager is on the main desktop.

The guymager main screen shows four disks. In our case disk WDC_WDS500G2B0A is the internal HDD (/dev/sda) and the Kingston data Traveler_3.0  is the Flash Drive. The third drive (linux loop) is the memory space CAINE uses to run the live USB/DVD.
Guymager supports two formats: Linux dd raw image and Expert Witness Format. Newer version of guymager also support the advanced forensic image format (AFF). Only DD and EWF support splitting the image onto subfile. This is recommended, as handling files larger than 4GB can be difficult on some filesystems (FAT). In this case we use EWF that support built-in metadata. EWF is a well supported format in most forensic packages (EnCase, Autopsy…etc).
this should be the location where the external hard drive is available. This is typically /media/root/<DISKNAME>. In this particular case, image verification is selected (which will make sure no errors have taken place during the capture).Select start 

6.เมื่อเสร็จ จะได้   CF010.e01

7.นำ Forensic image file  CF010.e01 ทำการวิเคราะห์ไฟล์โดยใช้ Autopsy 

A new page will open. Enter the details in ‘Case Name’ and ‘Base Directory’ . Then click on next to proceed to next step. 

Here in next step you have to enter the case number and Examiner details and click on finish to proceed to next step.
A new window will open .It will ask for add data source in Step 1. Select source type to add & browse the file Path (Disk Image and click on NEXT Option to proceed further.
In Step .  Configure ingest Modules I have chosen all the modules as I am looking for complete information on evidence device or disk or system  etc. and click next to proceed further.
After Process completion, it will show Forensic Investigation Report.


สรุป 

   1. การใช้ CAINE 11 จะป้องการเขียนข้อมูลลงหลักฐาน โดยจะใช้ Read-Only mode.   หากจะเขียนข้อมูลลง  Disk ต้องเปลี่ยน  writable mode ก่อน  (Unblock)

    2.  การเขียนข้อมูลลง External HDD ที่เป็นระบบ NTFS ต้องทำการเขียนคำสั่ง - #sudo ntfs-3g -o rw /dev/sda1 /media/sda1

If the user wants to mount and write on an NTFS media should instead use the "ntfs-3g" command (e.g., $ sudo ntfs-3g -o rw /dev/sda1 /media/sda1).

sudo ntfs-3g -o rw /device-path /your-mount-point

     3.ถ้าไม่สามารถ  boot USB ได้ให้ลองปิด  disable  UEFI (   If secureboot failed, try to disable it from UEFI.)

    4. สามารถใช้  guymager  ในการทำ Imager 

   5. ตรวจสอบ วันเวลา Time setting


Cerdit:

 https://www.caine-live.net

https://www.dfir.vn

http://az4n6.blogspot.com

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น


* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #computerforensic #ComputerForensics #dfir #forensics

#digitalforensics #investigation 

Thursday, September 10, 2020

Mobile Forensics:Cellebrite Reader Training Free online Course

Mobile Forensics:Cellebrite Reader Training Free online Course

UFED Reader  หรือ Cellebrite Reader  คือ  โปรแกรมช่วยให้ผู้ตรวจสอบและนักกฎหมาย, เจ้าหน้าที่สืบสวน, เจ้าหน้าที่พิสูจน์หลักฐาน สามารถจัดการกับปัญหาต่างๆที่เกี่ยวข้องกับการพิสูจน์หลักฐานของอุปกรณ์พกพา(โทรศัพท์)ในยุคปัจจุบัน Cellebrite Reader ช่วยผู้ตรวจสอบซึ่งปกติไม่ได้เกี่ยวข้องกับนิติวิทยาศาสตร์ดิจิทัลให้มีส่วนร่วมในการค้นหาไฟล์หลักฐานดิจิทัล

ฟรีหลักสูตรอบรม Cellebrite Reader นี้มีเวลา 45 วันนับจากเวลาที่ลงทะเบียน 


CELLEBRITE READER(READER)Mobile Forensics

Cellebrite Reader เป็นหลักสูตรระดับเริ่มต้น 1 วันที่ออกแบบมาเพื่อทำความคุ้นเคยกับผู้ตรวจสอบที่ไม่ใช่ด้านเทคนิคและนักกฎหมายมืออาชีพด้วยเครื่องมือ Reader ที่ง่ายและฟรี Cellebrite Reader ช่วยให้ผู้ตรวจสอบได้ใช้ Universal Forensic Extraction Device (UFED) จัดทำรายงาน  เพื่อให้พวกเขาสามารถทำการค้นหา แท็ก และเน้นรายการหลักฐานและสร้างรายงาน 

Free Online Mobile Forensics Training

หลักสูตรนี้ต้องการไฟล์ต่อไปนี้ ลิงค์ด้านล่างนี้เป็นข้อมูลอัปเดตที่พบในโมดูลของหลักสูตร กรุณาใช้ลิงค์ด้านล่าง
* อย่าลืมดาวน์โหลดและคลายซิป / แตกไฟล์ก่อนเปิดในโปรแกรม Reader หมายเหตุ: ไฟล์นี้มีขนาดประมาณ 4GB และจะใช้เวลาดาวน์โหลดนานพอสมควร
Course Content





พูดถึงความสำคัญของ mobile devices ในการตรวจสอบโดย:
  • การระบุวิธีการที่เป็นไปได้ที่อุปกรณ์เคลื่อนที่ถูกใช้ในก่ออาชญากรรม
  • การกำหนดประเภทของอุปกรณ์เคลื่อนที่ในตลาดและวิธีที่คุณสามารถระบุได้
  • ระบุตำแหน่งที่เป็นไปได้ที่หลักฐานเก็บอยู่


Cellbrite Extraction Methods



รวบรวมพยานหลักฐานแวดล้อม

A. Physical Evidence
  • Fingerprints  ตรวจสอบลายนิ้วมือ
B. Surveillance Video Footage  ตรวจสอบภาพจากกล้องวงจรปิด ในสถานที่เกิดเหตุ และบริเวณใกล้เคียง
C. Mobile Device Evidence
  • Hardware Information   
    •         IMEI , Model
  • Cell Phone Provider Evidence
    • ชื่อและที่อยู่ Email ลงทะเบียนผู้ใช้โทรศัพท์ (credit address ,user address, email account)
  • Mobile Applications
    •  social media account   ตรวจสอบข้อมูลผู้ใช้มีบัญชีโซเชียลมีเดียที่เชื่อมโยงไปยังชื่อผู้ใช้เฉพาะที่ใช้ในข้อมูลของสมาชิก
    • video was recovered
    • Geolocation information ข้อมูลตำแหน่งทางภูมิศาสตร์ที่เกี่ยวข้องกับไฟล์วิดีโอ
Call log


ด้านล่างนี้คือหลักฐานเฉพาะบางประเภทที่อาจพบได้ในอุปกรณ์มือถือ 

Fraud Investigations  การตรวจสอบทุจริต - Evidence Types

Homicide Investigations การสืบสวนคดีฆาตกรรม - Evidence Types
  • Address books
  • Email ,Notes and Letters
  • financial Asset Records
  • Internet Activity Logs
  • Legal Documents and Wills
  • Phone Records(calls)
  • Map and Location Information
  • Photos of victim/Subspect
  • Text Communications
Child Exploitation การแสวงหาประโยชน์จากเด็ก - Evidence Types
  • Chat Logs
  • Email ,Notes and Letters
  • Graphic Editing Software
  • Images and Video Files
  • Location Data
  • Inter Activity Logs
  • Peer-To-Peer software
  • Social Media Applications

แนวทางปฎิบัติในการเก็บหลักฐานทางดิจิทัล

  • หากคุณเชื่อว่าหลักฐานดิจิทัลมีส่วนเกี่ยวข้องกับการก่ออาชญากรรมให้ดำเนินการในทันทีโดยเก็บรักษาหลักฐานและอุปกรณ์ดิจิทัลไว้ โดยส่วนนี้ยังรวมถึงหลักฐานบนคลาวด์ เช่น เว็บไซต์โซเชียลมีเดีย , บันทึกโทรศัพท์มือถือและที่เก็บข้อมูลระยะไกล (remote storage)
  • คุณควรพิจารณาถึงพื้นฐานทางกฎหมายที่จำเป็นในการยึดอุปกรณ์หลักฐานดิจิทัล คุณได้รับความยินยอมหรือไม่ (consent) ? คุณมีหมายค้นหรือไม่ (a search warrant) ? อำนาจตามกฎหมายและขอบเขตการสอบสวนของคุณจะมีผลต่อการตรวจทางนิติวิทยาศาสตร์ดิจิทัล
  • อย่าเข้าถึงหรือค้นหาเนื้อหาของอุปกรณ์โดยไม่ใช้แนวทางปฏิบัติที่ดีที่สุดทางนิติวิทยาศาสตร์ดิจิทัล(digital forensic best practices )เพื่อรักษาความสมบูรณ์ของหลักฐานและการยอมรับหลักฐาน ซึ่งหมายความว่า อย่าเชื่อมต่ออุปกรณ์โดยตรงโดยเนื่องจากการเข้าถึงอุปกรณ์สามารถเปลี่ยนไฟล์หรือทำลายข้อมูลได้
Location Information Summary
มี3 วิธีในการรับข้อมูลตำแหน่งจากอุปกรณ์มือถือ ได้แก่ GPS, Wi-Fi Hotspot และ Cell Tower Triangulation
  • GLOBAL POSITIONNING SYSEM (GPS)ใช้เครือข่ายดาวเทียมเพื่อกำหนดตำแหน่งของผู้ใช้บนโลก มีประโยชน์สำหรับแอพพลิเคชั่น GPS และการนำทาง แต่อาจใช้กับแอปพลิเคชันโซเชียลมีเดียจำนวนมากเมื่อโพสต์หรือแชร์เนื้อหา
  • WI-FI HOTSPOTS อุปกรณ์เคลื่อนที่จำนวนมากบันทึกตำแหน่งของเครือข่าย Wi-Fi ที่รู้จักและจะแจ้งให้ผู้ใช้เข้าร่วมเครือข่ายที่ "จดจำ" เมื่ออุปกรณ์อยู่ในระยะ
  • CELL TOWER TRIANGULATION วิธีนี้อาศัยความแรงของสัญญาณจากเสาสัญญาณโดยรอบในระยะของอุปกรณ์เคลื่อนที่ อุปกรณ์เคลื่อนที่จะบันทึกตำแหน่งโดยอิงจากข้อมูลนี้ แต่โดยปกติแล้วข้อมูลนี้จะมีความแม่นยำน้อยที่สุดในประเภทข้อมูลตำแหน่งทั้งหมด


Question 



Cellebrite Certificate of Attendance Cellebrite Reader Course


ศึกษาเพิ่มเติม Cellebrite Reader



  สรุป  หลักสูตร Cellebrite Reader Training  Course  ฟรี
   - เป็นหลักสูตรฟรีที่คุ้มค่าและเนื้อหาเยอะสำหรับผู้ที่ศึกษาด้าน Mobile Forensics มีวิดิโอให้ศึกษาเข้าใจง่ายและ Case Study
   - มี Cellebrite Reader ให้ใช้ฟรี พร้อม UFDR Practical file  Reader Practical.ufdr
   - Cellebrite Reader ไม่ต้องติดตั้งโปรแกรมบนเครื่อง
   - มีทดสอบท้ายบทเรียนด้วย
   - ได้รับ Cellebrite Certificate of Attendance Cellebrite Reader Course  เมื่อเรียนจบหลักสูตรและ CPE


#WINDOWSFORENSIC #COMPUTERFORENSICS #DFIR #FORENSICS #DIGITALFORENSICS #COMPUTERFORENSIC #INVESTIGATION #CYBERCRIME #FRAUD

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง ADMIN เพื่อแก้ไขต่อไป
ขอบคุณครับ



Tuesday, September 8, 2020

Digital Forensics:"ข้อมูลคอมพิวเตอร์"

Digital Forensics:"ข้อมูลคอมพิวเตอร์"

"ข้อมูลคอมพิวเตอร์" ตาม พรบ.คอมพิวเตอร์ ไม่รวมถึง ข้อมูลที่บันทึกไว้ในสื่อที่แยกออกมาจากระบบคอมพิวเตอร์
นิยามคำว่า “ข้อมูลคอมพิวเตอร์” หมายความว่า ข้อมูล ข้อความ คำสั่ง ชุดคำสั่ง หรือสิ่งอื่นใด "บรรดาที่อยู่ในระบบคอมพิวเตอร์"...
(หมายเหตุ อาจตีความ ข้อมูลคอมพิวเตอร์ ในคำนิยาม ".. ในสภาพที่ระบบคอมพิวเตอร์อาจประมวลผลได้..." ได้ 2 แนวทาง 1. ต้องเชื่อมต่อกับระบบคอมพิวเตอร์ จึงจะเป็นข้อมูลคอมพิวเตอร์ได้ หรือ 2. ไม่จำเป็นต้องเชื่อมต่อกับระบบคอมพิวเตอร์ ยังสามารถถือเป็นข้อมูลคอมพิวเตอร์ได้)
เช่น ข้อมูลที่ใส่แผ่น CD หรือ ใน Handy Drive แล้ว ดึงออกจากตัวเครื่องคอมพิวเตอร์
การทำลายแผ่น CD หรือ ใน Handy Drive ขณะแยกออกจากเครื่องคอมพิวเตอร์ ไม่ผิดทำให้เสียหาย ทำลายข้อมูลคอมพิวเตอร์ตาม พรบ.คอมพิวเตอร์ฯ มาตรา 9 (แต่ยังคงผิดฐานทำให้เสียทรัพย์ ตามประมวลกฎหมายอาญา มาตรา 358 ในส่วนของตัววัสดุบันทึกข้อมูล)
"ข้อมูลคอมพิวเตอร์" ตาม พรบ.คอมพิวเตอร์ จึงต่างกับ พยานหลักฐานดิจิทัล พยานหลักฐานอิเล็กทรอนิกส์ ที่รวมถึงข้อมูลที่บันทึกในรูปของรหัสเลขฐานสอง หรือในรูปของข้อมูลดิจิทัล ทุกกรณี
พรบ.ว่าด้วยการกระทำความผิดเกี่ยวกับคอมพิวเตอร์ พ.ศ.2550

มาตรา 3 ในพระราชบัญญัตินี้

“ข้อมูลคอมพิวเตอร์” หมายความว่า ข้อมูล ข้อความ คำสั่ง ชุดคำสั่ง หรือสิ่งอื่นใดบรรดาที่อยู่ในระบบคอมพิวเตอร์ ในสภาพที่ระบบคอมพิวเตอร์อาจประมวลผลได้ และให้หมายความรวมถึงข้อมูลอิเล็กทรอนิกส์ตามกฎหมายว่าด้วยธุรกรรมทางอิเล็กทรอนิกส์ด้วย

มาตรา 9 = Computer Data Interference

ผู้ใดทำให้เสียหาย ทำลาย แก้ไข เปลี่ยนแปลง หรือเพิ่มเติม ไม่ว่าทั้งหมด หรือบางส่วนซึ่งข้อมูลคอมพิวเตอร์ของผู้อื่นโดยมิชอบ ต้องระวางโทษจำคุกไม่เกินห้าปี ...
 

ข้อมูลอิเล็กทรอนิกส์


ข้อมูลคอมพิวเตอร์

 

Computer Data


พยานหลักฐานดิจิทัล


 
 
ที่มา:Facebook  Pakorn Dharmaroj ท่านอาจารย์ ปกรณ์ ธรรมโรจน์ สำนักงานอัยการสูงสุด 8 ก.ย 2563
 
ขอขอบคุณ ท่านอาจารย์. ปกรณ์ ธรรมโรจน์ สำนักงานอัยการสูงสุด ขออนุญาตแชร์เป็นวิทยาทาน

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ


#WindowsForensic #computerforensic #ComputerForensics #dfir #forensics #digitalforensics #investigation #cybercrime #fraud #DigitalEvidence #CyberCrime#

พยานหลักฐานดิจิทัล

 

Sunday, September 6, 2020

Digital Forensics:How to Wipe Hard Disk with OSforensics

Digital Forensics:How to Wipe Hard Disk with OSforensics

Overwriting and filling the data and drives with zeroes.

OSforensics can wipe data and erase drives by overwriting data.

 
Step 1 Open OSForensics  3.3 Free Version.

Step 2 Select Drive Preparation  > Physical drive (Removable 14.41 GB K:FAT32)
Datatraveler 100 g3 16 GB

Write a data pattern to the entire drive "00".

Step 3. Click Write pattern.
Until Progress is 100%.

Step 4. Click Verify pattern.

Step 5. check pattern
Open Windows Explorer and navigate to the FTK Imager 3.4.0.1
In FTK’s main window, go to File and click on add Evidence Item.

Step 6.Select Physical Drive as the source evidence type. Click on Next.
Select the actual physical drive from the drop down list and click on Finish.
Open the Physical Drive of my flash drive in FTK Imager. The contents of the Physical Drive appear in the Evidence Tree Pane. "00"


Credit: PassMark OSForensics 

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ


หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

#wipe #secureerase #diskwiping #Sanitization #Computer Forensics #DigitalForensics#WINDOWSFORENSIC #COMPUTERFORENSICS #DFIR #FORENSICS #DIGITALFORENSICS #COMPUTERFORENSIC #INVESTIGATION #CYBERCRIME #FRAUD

Volatility Lab

Volatility Lab  Image Wanna.vmem P.73 windows.info #python3  vol.py   -f '/home/kali/Desktop/Wanna/Wanna-MEM.vmem' windows.info     ...